Data Processing Agreement
Last updated: 3 May 2026
1. Introduction
This Data Processing Agreement ("DPA") forms part of the agreement between Zappwise AB ("Zappwise," "Processor," "we," "us," or "our") and the customer identified in the relevant order, signup, or service agreement ("Customer," "Controller," or "you") for the use of the Zappwise platform and related services (the "Service"), as governed by the Zappwise Terms of Service available at zappwise.com/terms (the "Agreement").
This DPA reflects the parties' agreement on the processing of personal data by Zappwise on behalf of Customer in accordance with the requirements of Regulation (EU) 2016/679 (the "GDPR"), the UK GDPR, the Swedish Data Protection Act (Lag 2018:218), and other applicable data protection laws.
In the event of a conflict between this DPA and the Agreement, this DPA prevails on data protection matters.
2. Acceptance
This DPA is automatically incorporated into the Agreement when Customer creates an account or accepts the Terms of Service. Customers requiring a signed counterpart may request one by contacting legal@zappwise.com; in such cases, both parties will execute a copy of this DPA, and the executed copy will prevail over the click-through version.
3. Definitions
Capitalised terms not defined in this DPA have the meanings given in the GDPR or the Agreement. For the purposes of this DPA:
- "Customer Personal Data" means personal data processed by Zappwise on behalf of Customer through the Service.
- "Data Subject" means an identified or identifiable natural person to whom Customer Personal Data relates.
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data.
- "Subprocessor" means any third party engaged by Zappwise to process Customer Personal Data.
- "Standard Contractual Clauses" or "SCCs" means the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914), as amended.
4. Roles and Scope
4.1 Roles of the parties
In relation to Customer Personal Data, Customer is the Controller and Zappwise is the Processor. Where Customer acts as a processor on behalf of a third party (e.g., a brokerage acting on behalf of property sellers), Zappwise acts as a sub-processor and the obligations in this DPA flow accordingly.
4.2 Subject matter and duration
The subject matter of the processing is the provision of the Service. The duration of the processing is the term of the Agreement, plus any post-termination period required for return or deletion of data.
4.3 Nature, purpose, and categories
The nature, purpose, types of personal data, and categories of data subjects processed under this DPA are described in Annex I.
5. Customer Instructions
Zappwise will process Customer Personal Data only on documented instructions from Customer, including with regard to international transfers, unless required to do so by applicable law. The Agreement, this DPA, and Customer's use of the Service constitute Customer's complete and final documented instructions to Zappwise. Additional or alternative instructions must be agreed in writing.
If Zappwise believes that an instruction violates the GDPR or other applicable data protection law, Zappwise will inform Customer without undue delay and may suspend the relevant processing pending resolution.
6. Confidentiality
Zappwise will ensure that personnel authorised to process Customer Personal Data are bound by appropriate confidentiality obligations, whether contractual or statutory, and have received training on their data protection responsibilities.
7. Security Measures
Zappwise will implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing.
A description of the security measures in place is set out in Annex II. Zappwise may update these measures from time to time, provided that the updates do not materially decrease the level of protection.
8. Subprocessors
8.1 General authorisation
Customer grants Zappwise general authorisation to engage Subprocessors to assist in providing the Service, subject to the conditions in this Section 8.
8.2 Current subprocessors
Zappwise's current Subprocessors are listed in Annex III and on our website at zappwise.com/subprocessors.
8.3 Changes to subprocessors
Zappwise will provide Customer with at least 30 days' advance notice of any intended addition or replacement of Subprocessors, by email or through a notice on the Service. Customer may object to a new Subprocessor on reasonable data protection grounds within 15 days of the notice. If the parties cannot agree on a resolution, Customer may terminate the affected portion of the Service for convenience without penalty.
8.4 Subprocessor obligations
Where Zappwise engages a Subprocessor, Zappwise will impose data protection obligations on the Subprocessor that are no less protective than those in this DPA, and will remain liable to Customer for the Subprocessor's performance of those obligations.
9. Data Subject Rights
Taking into account the nature of the processing, Zappwise will provide reasonable assistance to Customer, by appropriate technical and organisational measures, in fulfilling Customer's obligations to respond to requests from Data Subjects exercising their rights under the GDPR (including rights of access, rectification, erasure, restriction, portability, and objection).
If Zappwise receives a request from a Data Subject relating to Customer Personal Data, Zappwise will not respond to the request directly (except to acknowledge receipt and direct the Data Subject to Customer) and will forward the request to Customer without undue delay.
10. Personal Data Breaches
Zappwise will notify Customer of a Personal Data Breach affecting Customer Personal Data without undue delay, and in any event within 72 hours of becoming aware of the breach. The notification will include, to the extent known at the time:
- A description of the nature of the breach, including categories and approximate number of Data Subjects and records concerned.
- The likely consequences of the breach.
- Measures taken or proposed to address the breach and mitigate its effects.
- Contact details for further information.
Zappwise will provide reasonable assistance to Customer in meeting Customer's own breach notification obligations under applicable data protection law.
11. Data Protection Impact Assessments
Where required under Article 35 or 36 of the GDPR, Zappwise will provide reasonable assistance to Customer with data protection impact assessments and prior consultations with supervisory authorities, taking into account the nature of the processing and the information available to Zappwise.
12. International Data Transfers
Customer authorises Zappwise to transfer Customer Personal Data outside the European Economic Area (EEA), the United Kingdom, and Switzerland to the extent necessary to provide the Service, including transfers to Subprocessors located in such jurisdictions.
Where Zappwise transfers Customer Personal Data from the EEA, UK, or Switzerland to a country that has not been recognised as providing an adequate level of protection, Zappwise will rely on:
- The European Commission's Standard Contractual Clauses (Decision (EU) 2021/914), incorporated into this DPA by reference; or
- The UK International Data Transfer Addendum or UK IDTA, where transfers originate from the UK; or
- Other valid transfer mechanisms recognised under applicable law.
Where the SCCs apply, Module Two (Controller to Processor) applies between Customer and Zappwise. Where Customer acts as a processor on behalf of a third-party controller, Module Three (Processor to Sub-processor) applies. The parties agree to the docking clause and to the optional clauses as set out in Annex IV.
13. Audits
Zappwise will make available to Customer, on reasonable request, information necessary to demonstrate compliance with this DPA. Audit rights operate as follows:
- Standard practice: Zappwise will provide third-party audit reports (e.g., SOC 2, ISO 27001) once available, and will respond to reasonable security questionnaires (such as SIG Lite, CAIQ, or equivalent) at no charge.
- On-site audits: Customer may conduct an on-site audit only where (a) a third-party report is unavailable or insufficient to address Customer's specific compliance concern, (b) Customer provides at least 30 days' written notice, (c) the audit is conducted during normal business hours and does not unreasonably interfere with Zappwise's operations, (d) Customer bears its own costs and reimburses Zappwise's reasonable costs, and (e) the auditor signs an appropriate confidentiality agreement.
- Frequency: On-site audits may be conducted no more than once per year, except where required by a supervisory authority or following a material Personal Data Breach affecting Customer.
Customer will provide Zappwise with a copy of any audit report and treat the report as Zappwise's confidential information.
14. Return and Deletion of Data
Upon termination of the Agreement, Zappwise will, at Customer's choice, delete or return all Customer Personal Data and delete existing copies, unless applicable law requires continued storage. Deletion will be completed within 30 days of termination, subject to Zappwise's standard backup retention schedule (after which backup copies are deleted in the ordinary course).
Customer may request export of Customer Personal Data through the Service's standard export functionality at any time during the term of the Agreement.
15. Liability
Each party's liability arising out of or related to this DPA is subject to the limitations of liability in the Agreement. Nothing in this DPA limits or excludes liability that cannot be limited or excluded under applicable law.
16. Term and Termination
This DPA takes effect on the date Customer accepts it (or executes a counterpart) and remains in force for the duration of the Agreement. Provisions that by their nature should survive termination (including obligations regarding return or deletion of data, confidentiality, and liability) will survive.
17. Governing Law
This DPA is governed by the laws of Sweden, without regard to its conflict of laws principles. Disputes arising out of or relating to this DPA are subject to the exclusive jurisdiction of the courts of Stockholm, Sweden, except where mandatory law provides otherwise.
Where the SCCs apply, the governing law and forum provisions of the SCCs apply to the SCCs themselves, in accordance with their terms.
18. Contact
Questions about this DPA or data protection matters should be directed to:
Zappwise AB
Norrsunda Skoby 126, 195 95 Rosersberg, Sweden
Org. nr: 559495-5337
Email: privacy@zappwise.com
Annex I, Description of Processing
A. List of parties
Data exporter (Controller): The Customer identified in the Agreement.
Data importer (Processor): Zappwise AB, Norrsunda Skoby 126, 195 95 Rosersberg, Sweden, Org. nr: 559495-5337. Contact: privacy@zappwise.com.
B. Description of transfer
Categories of Data Subjects: Customer's authorised users (employees, contractors, agents); end users or clients of Customer (e.g., real estate agents, property owners) whose personal data Customer chooses to upload or process through the Service.
Categories of Personal Data: Account and contact information (name, email, phone, company, role); authentication credentials; usage and log data; IP addresses; uploaded media files (property photos and related metadata); listing content and descriptions; communications with Zappwise.
Special categories of data: Not intended. Customer agrees not to upload special category data (Article 9 GDPR) or criminal conviction data (Article 10 GDPR) through the Service. Property photos must not contain identifiable individuals.
Frequency of transfer: Continuous, for the duration of the Agreement.
Nature of processing: Hosting, storage, transmission, processing, organisation, and display of Customer Personal Data to provide the Service, including media processing, listing creation, and related platform functions.
Purpose of processing: Providing, maintaining, securing, and supporting the Service in accordance with the Agreement.
Retention period: For the duration of the Agreement, plus a 30-day grace period for export, after which Customer Personal Data is deleted in accordance with Section 14.
Subprocessor processing: As described in Annex III.
C. Competent supervisory authority
The Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) acts as the competent supervisory authority for Zappwise. Where Customer is established in another EEA Member State, the supervisory authority of Customer's Member State may also be competent.
Annex II, Technical and Organisational Measures
Zappwise implements the following technical and organisational measures to protect Customer Personal Data. These measures are reviewed periodically and may be updated provided the level of protection is not materially reduced.
1. Access control
- Role-based access control (RBAC) restricts access to Customer Personal Data to authorised personnel on a need-to-know basis.
- Multi-factor authentication (MFA) is required for administrative access to production systems.
- Access rights are reviewed periodically and revoked promptly upon termination of personnel.
2. Encryption
- Customer Personal Data is encrypted in transit using industry-standard TLS.
- Customer Personal Data is encrypted at rest using cloud provider-managed encryption keys (AES-256 or equivalent).
3. Network and infrastructure security
- The Service is hosted on Google Cloud Platform, which provides physical security, network segmentation, DDoS protection, and infrastructure-level security controls.
- Production systems are isolated from development and testing environments.
- Firewall and security group rules restrict network access to authorised services only.
4. Application security
- Secure software development practices, including code review and dependency monitoring.
- Vulnerability scanning and patching of dependencies.
- Logging and monitoring of security-relevant events.
5. Operational security
- Backups are performed regularly and stored encrypted.
- Incident response procedures with defined escalation paths.
- Personnel are required to complete security and data protection training.
6. Business continuity
- Use of cloud infrastructure with redundancy and failover capabilities.
- Documented disaster recovery procedures.
7. Vendor management
- Subprocessors are evaluated for security and data protection practices before engagement.
- Data processing agreements are in place with all Subprocessors.
Annex III, Subprocessors
The following Subprocessors are engaged by Zappwise as of the date of this DPA. The current list is also available at zappwise.com/subprocessors.
Google Cloud Platform (Google LLC). Service provided: cloud infrastructure hosting, including compute and supporting services. Location of processing: European Union (primary), with possible transfers to the United States. Transfer mechanism: Standard Contractual Clauses, as set out in Google's Cloud Data Processing Addendum.
This list will be updated as Subprocessors are added, replaced, or removed in accordance with Section 8 of this DPA.
Annex IV, Standard Contractual Clauses
Where international transfers under Section 12 require the use of the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914), the SCCs are incorporated into this DPA by reference, with the following selections:
- Module Two (Controller to Processor) applies between Customer (as data exporter) and Zappwise (as data importer) where Customer is the Controller of Customer Personal Data.
- Module Three (Processor to Sub-processor) applies where Customer acts as a processor on behalf of a third-party controller and Zappwise acts as Sub-processor.
- Clause 7 (Docking clause): the optional docking clause applies.
- Clause 9 (Use of sub-processors): Option 2 (general written authorisation) applies, with at least 30 days' advance notice as set out in Section 8.3.
- Clause 11 (Redress): the optional language regarding independent dispute resolution does not apply.
- Clause 17 (Governing law): the SCCs are governed by the laws of Sweden.
- Clause 18 (Choice of forum): the courts of Stockholm, Sweden, are competent.
- Annex I, II, and III to the SCCs: completed by reference to Annexes I, II, and III of this DPA.
For transfers originating from the United Kingdom, the UK International Data Transfer Addendum to the SCCs (the "UK IDTA") is incorporated by reference. The Tables of the UK IDTA are completed by reference to the corresponding sections of this DPA and the SCCs.
For transfers originating from Switzerland, the SCCs apply with the adaptations set out in the guidance of the Swiss Federal Data Protection and Information Commissioner (FDPIC), including references to the Swiss Federal Act on Data Protection.